Uniform-load high-security group key negotiation method

Through the construction of a negotiation interaction model and a design key aggregation and multi-signature collaborative aggregation mechanism, the existing group key negotiation protocol is solved, and the existing group key negotiation protocol is large-scale distributed environments is achieved, and efficient and secure group key negotiation is achieved.

CN120017271AActive Publication Date: 2025-05-16ZHEJIANG SCI-TECH UNIV
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510466638.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-15
Publication Date
2025-05-16
Estimated Expiration
2045-04-15

AI Technical Summary

Technical Problem

The existing group key negotiation protocols have problems such as high resource consumption, low efficiency, high computational complexity, and lack of effective resistance mechanisms for key control attacks in large-scale distributed environments.

Method used

Through the difference set, the negotiation interaction model is built, the number of decryption operations of each user is fixed, and the key aggregation and multi-signature collaborative aggregation mechanism is designed to achieve group key negotiation with high load and security.

Benefits of technology

It reduces computing overhead, improves execution efficiency, and operates efficiently in a large-scale distributed environment, provides strong security guarantees for dynamic membership and multi-party collaboration, and effectively prevents key control attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017271A_ABST
    Figure CN120017271A_ABST
Patent Text Reader

Abstract

The invention provides an even-load high-security group key negotiation method, which comprises the following steps of: generating a difference set, and calculating a negotiation interaction model for each user based on the difference set; a public and private key pair is generated for each user, each user serves as a sender user to execute first interaction and second interaction, and in the first interaction, each sender user encrypts a private key of the sender user and then sends the encrypted private key to a corresponding receiver user to obtain a first aggregation value; in the second interaction, each sender user encrypts the first aggregation value of the sender user and sends the encrypted first aggregation value to the corresponding receiver user to obtain a second aggregation value; and each user obtains a group session key by using a private key of the user and the second aggregation value through Hash operation. According to the scheme, the negotiation interaction model is constructed through the difference set, the decryption operation frequency of each user is fixed to be a constant to improve the execution efficiency, efficient operation can be achieved in a large-scale distributed environment, and powerful safety guarantee is provided for multi-party cooperation of dynamic members.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of data security, and in particular to a load-balanced high-security group key negotiation method. Background Art

[0002] With the widespread application of distributed systems and multi-party collaboration, secure and efficient data sharing has become an urgent problem to be solved. However, most of the current secure data sharing solutions rely on the Key Encapsulation Mechanism (KEM). Specifically, the KEM mechanism requires the data owner to encrypt the data with a symmetric key and encrypt the symmetric key with a public key, and then broadcast the encrypted key together with the data to the receiver. Although this mechanism can achieve one-to-many data sharing, it has the problems of high resource consumption and low efficiency in group data sharing, especially when the number of users is large, the communication and computing overhead will increase significantly. Therefore, although the KEM mechanism can operate efficiently in small-scale sharing, it obviously cannot meet the requirements of efficiency and security in large-scale distributed environments.

[0003] To address this problem, researchers proposed a group key negotiation method. The GKA protocol aims to generate a shared session key through multi-party negotiation and ensure secure communication between multiple parties through the key. However, most of the existing GKA protocols rely on the broadcast interaction model. In the broadcast model, each user needs to broadcast its key information to all other users in each round of the protocol. As the number of users increases, the communication and computing overhead of this method increases exponentially, which seriously restricts the scalability and execution efficiency of the protocol. Especially in distributed systems, users' computing power and network bandwidth may be limited. The high overhead of the broadcast interaction model will seriously affect the practicality of the protocol. In addition, most of the existing KGA protocols adopt an unbalanced interaction mode, that is, a fully trusted manager is responsible for generating session keys and distributing them to other users. In this mode, the initiator or leader of the protocol undertakes more computing and communication tasks. Especially in distributed systems, the uneven distribution of resources may cause some nodes to be overloaded, which in turn affects the security and reliability of the entire system. That is, in GKA, if the leader is attacked or fails, the security of the entire protocol will be threatened. More importantly, this unbalanced interaction mode makes some users' computing burden too heavy, especially in resource-limited environments, which may lead to protocol execution failure.

[0004] Moreover, in the GKA protocol, it is usually assumed that all users are completely trustworthy, that is, they will not intentionally disclose session keys or tamper with the execution process of the protocol. However, in actual applications, users are often semi-trustworthy. Some users are not completely honest and may even tamper with the key generation process through key control attacks to obtain illegal session keys. This attack method makes the protocol lose its security, and existing protocols generally lack effective resistance mechanisms to such attacks. In addition, the existing GKA protocol also has the problem of high computational complexity. The design of many protocols relies on complex mathematical structures. The construction and calculation process of these structures are relatively complex and do not support parallel execution. Although these structures have certain advantages in theory, their construction and calculation process are often very complex. They require users to process huge matrices or high-order equations in each round of interaction. As the number of users increases, the computing and storage overhead shows a large increase, resulting in a significant decrease in the execution speed of the protocol and the response time of the system. Especially in resource-constrained environments, users cannot bear such a high computing and storage burden. Therefore, these protocols usually cannot fully utilize the parallelism of distributed computing resources, thereby limiting their application in large-scale distributed systems. Summary of the invention

[0005] The embodiment of the present application provides a load-balanced high-security group key negotiation method, which constructs a negotiation interaction model through difference sets. It not only fixes the number of decryption operations for each user to a constant to reduce computing overhead and improve execution efficiency, but also can run efficiently in a large-scale distributed environment, providing strong security protection for dynamic member multi-party collaboration.

[0006] In a first aspect, an embodiment of the present application provides a difference set extended group key negotiation method, the method comprising: Generate a difference set, and calculate a negotiation interaction model for each user in the blockchain based on the difference set, wherein the negotiation interaction model defines the interaction objects of the user, and each user has the same number of interaction objects, and each user and all corresponding interaction objects in the negotiation interaction model are grouped as a group. In all groups, the number of times any two users appear together in different groups is a preset constant, wherein the interaction objects are other users in the blockchain; Generate a public-private key pair for each user in the blockchain, and use each user as a sender user to perform a first interaction and a second interaction. In the first interaction, each sender user encrypts its own private key and sends it to the corresponding receiver user, and the receiver user aggregates all the received encrypted private keys to obtain a first aggregate value; in the second interaction, each sender user encrypts its own first aggregate value and sends it to the corresponding receiver user, and the receiver user aggregates all the received encrypted first aggregate values ​​to obtain a second aggregate value, wherein the interaction object in the negotiation interaction model corresponding to the sender user is the corresponding receiver user; Each user uses his own private key and the second aggregate value to obtain the group session key through a hash operation.

[0007] In a second aspect, an embodiment of the present application provides a load-balanced group key negotiation method, including: Calculate the negotiation interaction model for each user in the blockchain using the same method as the first aspect; Generate a public-private key pair for each user in the blockchain, and use each user as a sender user to perform the third interaction and the fourth interaction. In the third interaction, each sender user encrypts its own private key and sends it to the corresponding receiver user. The receiver user aggregates all the received encrypted private keys to obtain a third aggregate value, and adds a BLS signature to the third aggregate value to obtain a first signature value. In the fourth interaction, each sender user encrypts its own third aggregate value and sends it to the corresponding receiver user in conjunction with the first signature value. The receiver user aggregates all the received encrypted third aggregate values ​​to obtain a fourth encrypted aggregate value, and aggregates all the received first signature values ​​to obtain a second signature value. The interaction object in the negotiation interaction model corresponding to the sender user is the corresponding receiver user. Each user verifies the second signature value, and after passing the verification, uses its own private key and the fourth aggregate value to obtain the group session key through a hash operation.

[0008] In a third aspect, an embodiment of the present application provides an electronic device, including a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to execute a difference set extended group key negotiation method or a load-sharing group key negotiation method.

[0009] In a fourth aspect, an embodiment of the present application provides a readable storage medium, in which a computer program is stored. The computer program includes a program code for controlling a process to execute a process, and the process includes a difference set extended group key negotiation method or a load-balanced group key negotiation method.

[0010] The main contributions and innovations of the present invention are as follows: The embodiment of the present application constructs a parallel distributed cluster interaction model based on difference sets, and uses the combinatorial mathematical structure of difference sets to ensure the confidentiality and integrity of multi-party interaction data in a distributed environment, while revealing the SDR evolution mechanism to help quickly reach group key negotiation; the developed group key negotiation algorithm that supports parallel interaction defines serial and parallel interaction modes to avoid excessive resource consumption and single point failure risks; the designed key aggregation and multi-signature collaborative aggregation mechanism effectively prevents key control attacks and ensures fair and secure negotiations. It not only fixes the number of decryption operations for each user to a constant to reduce computing overhead and improve execution efficiency, but also can run efficiently in a large-scale distributed environment, providing strong security guarantees for dynamic member multi-party collaboration.

[0011] Details of one or more embodiments of the present application are set forth in the following drawings and description to make other features, objects, and advantages of the present application more readily apparent. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings: Figure 1 is a flow chart of a difference set extended group key negotiation method according to an embodiment of the present application; Figure 2 is a schematic diagram of a group mapping table according to an embodiment of the present application; Figure 3 It is a schematic diagram of the hardware structure of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION

[0013] Exemplary embodiments will be described in detail herein, examples of which are shown in the accompanying drawings. When the following description refers to the drawings, the same numbers in different drawings represent the same or similar elements unless otherwise indicated. The implementations described in the following exemplary embodiments do not represent all implementations consistent with one or more embodiments of this specification. Instead, they are merely examples of devices and methods consistent with some aspects of one or more embodiments of this specification as detailed in the appended claims.

[0014] It should be noted that: in other embodiments, the steps of the corresponding method are not necessarily performed in the order shown and described in this specification. In some other embodiments, the steps included in the method may be more or less than those described in this specification. In addition, a single step described in this specification may be decomposed into multiple steps for description in other embodiments; and multiple steps described in this specification may be combined into a single step for description in other embodiments.

[0015] Embodiment 1 The embodiment of the present application provides a difference set extended interactive group key negotiation method, which constructs a negotiation interaction model through a difference set, not only fixes the number of decryption operations of each user to a constant to reduce computing overhead and improve execution efficiency, but also can run efficiently in a large-scale distributed environment, providing strong security guarantee for dynamic member multi-party collaboration. Specifically, reference Figure 1 , the method comprising: Generate a difference set, and calculate a negotiation interaction model for each user in the blockchain based on the difference set, wherein the negotiation interaction model defines the interaction objects of the user, and each user has the same number of interaction objects, and each user and all corresponding interaction objects in the negotiation interaction model are grouped as a group. In all groups, the number of times any two users appear together in different groups is a preset constant, wherein the interaction objects are other users in the blockchain; Generate a public-private key pair for each user in the blockchain, and use each user as a sender user to perform a first interaction and a second interaction. In the first interaction, each sender user encrypts its own private key and sends it to the corresponding receiver user, and the receiver user aggregates all the received encrypted private keys to obtain a first aggregate value; in the second interaction, each sender user encrypts its own first aggregate value and sends it to the corresponding receiver user, and the receiver user aggregates all the received encrypted first aggregate values ​​to obtain a second aggregate value, wherein the interaction object in the negotiation interaction model corresponding to the sender user is the corresponding receiver user; Each user uses his own private key and the second aggregate value to obtain the group session key through a hash operation.

[0016] In some embodiments, in the process of generating the difference set, let α be the multiplication group Generator of , the set of integers It forms a cyclic difference set with parameters [q,m], where the trace function is defined as Based on this, we can get a parameter A combination of designs, in which is the order of the difference set, and the parameters [q,m] are the classical parameters in the projective set. are the parameters of the combined design.

[0017] For example, using the parameters PG (4, 2) with m = 4, q = 2, starting from any initial state, the difference set is calculated as , and then based on the difference set D, a combined interval design with parameters (15, 7, 3) is expanded as shown in Table 1. The combined interval design represents a grouping situation that satisfies the parameters (15, 7, 3), where 15 corresponds to the number of users in the blockchain, 7 corresponds to the number of users in each group, and 3 corresponds to the number of times any two users appear together in different groups.

[0018] Table 1 Combined interval design with parameters (15, 7, 3)

[0019] That is to say, in the step of "calculating a negotiation interaction model for each user in the blockchain based on a difference set", the difference set is normalized to obtain a normal difference set, and the normal difference set is cyclically bitwise modulo addition based on a preset extended parameter to obtain a group mapping table, and a negotiation interaction model is assigned to the users in the blockchain based on the group mapping table, wherein the extended parameter includes the number of users in the blockchain, the number of users in each group, and the number of times any two users appear together in different groups.

[0020] Specifically, the normalization operation is to change the first element in the difference set to 0, and perform modular addition operations on the remaining elements in turn. For example, there is a difference set , first calculate the additive inverse of the first element 5 modulo 15, which is 10. Based on this, calculate the value of each element after the modular addition operation on 10 modulo 15: 6+10(mod15)=1; 7+10(mod 15)=2; 9+10(mod 15)=4; 10+10(mod 15)=5; 13+10(mod 15)=8; 0+10(mod 15)=10. Then change the first element 5 to 0, and the normalized normal difference set is {0,1,2,4,5,8,10}.

[0021] Then, based on the extended parameters, the normal difference set is subjected to a cyclic modular addition operation to generate a group mapping table, wherein the group mapping table is as follows: Figure 2 As shown by Figure 2 It can be seen that the generated group mapping table meets the SDR requirements. Figure 2 0-14 represent users in the blockchain, and each row represents a group. Figure 2 It can be seen that the number of users in each group and the number of times any two users appear together in different groups are both 3.

[0022] Specifically, this scheme explores the adaptive application of difference sets in the construction of distributed multi-party interaction models, reveals the evolution mechanism of System of Distinct Representatives (SDR) in the construction of distributed multi-party interaction models, defines a distributed interaction model construction method based on SDR extension, and effectively supports the rapid achievement of group key negotiation.

[0023] In some specific embodiments, the first interaction and the second interaction are performed in a serial interaction manner, that is, an interaction order is assigned to each sending user. In the first interaction, each sending user encrypts its own private key according to the interaction order and sends it to the corresponding receiving user. In the second interaction, each sending user encrypts its own first aggregate value according to the interaction order and sends it to the corresponding receiving user.

[0024] Exemplarily, the first interaction and the second interaction are serially executed using a serial interaction algorithm. In the first interaction, the algorithm traverses each user in the blockchain. , and in the group mapping table Internally for each grouped element ,Will Update the elements in In , where j is 1 to k-1, that is, in the first interaction, each sender user's own private key is sequentially encrypted and sent to the corresponding receiver in a traversal manner, and then the receiver aggregates all the received encrypted private keys to obtain a first aggregate value. It is worth mentioning that the number of encrypted private keys received by each receiver is the number of group members minus one, that is, only when the number of encrypted private keys received by the receiver is the number of group members minus one, all encrypted private keys are aggregated to obtain the first aggregate value.

[0025] In the second interaction, the encrypted first aggregate value of each sender user is sent to the corresponding receiver user in sequence by traversal. In the serial second interaction, the algorithm traverses the group mapping table Each element in , and find the smallest positive integer , so that , using this smallest positive integer To update the user Interaction model The sending is thus completed, where N is the number of users in the blockchain.

[0026] Specifically, since the group mapping table is constructed based on the normalized difference set, it can be obtained by The data is transmitted in a serial interaction algorithm as follows: First interaction: For i=0 to N-1, execute: For j=1 to k-1, execute: 1. .

[0027] Second interaction: For i=1 to N-1, execute: For j=1 to k-1, execute: 1. Find the smallest positive element , so that: .

[0028] 2. .

[0029] In some specific embodiments, the first interaction and the second interaction are performed in a parallel interaction manner, that is, in the first interaction, all sending users simultaneously encrypt their own private keys and send them to the corresponding receiving users, and in the second interaction, each sending user simultaneously encrypts its own first aggregate value and sends it to the corresponding receiving user.

[0030] Exemplarily, the first interaction and the second interaction are serially executed using a parallel interaction algorithm, and the variable dis is initialized, and the value of dis is the number i of the current user. In the first interaction, the parallel interaction algorithm traverses each element in D ,calculate , and the user corresponding to the index is used as the interaction model of the current user, so that each sender user's own private key is encrypted in parallel and sent to the corresponding receiver, where D is the difference set, j ranges from 1 to k-1, and k is the number of users in the group.

[0031] In the second interaction, the parallel interaction algorithm iterates over each element in the difference set. , and find the smallest positive integer , so that , using this smallest positive integer To update the user Interaction model .

[0032] The formula of the parallel interaction algorithm is as follows: First interaction: 1. Set dis=1; 2. For j=1 to k-1, execute:

[0033] Second interaction: 3. For j=1 to k-1, execute: (1) Find the smallest positive integer , so that:

[0034] (2)

[0035] In some embodiments, given a security parameter , based on safety parameters Generate a public-private key pair for each user in the blockchain ,in, is Randomly selected from , g is the generator of the cyclic group G.

[0036] In some embodiments, in the first interaction, each sender encrypts its own private key through ElGamal, numbered The receiving user receives the The encrypted private key is in the form of, where sen is The index of the sending user, rec is the index of the receiving user, represents a random value chosen by the sender user for the receiver user, is the subkey of the sending user, The public key of the recipient user.

[0037] Specifically, in the first interaction, each user in each group will receive the encrypted private keys of k-1 users, where k is the number of users in the group. The formula for the receiving user to aggregate all the received encrypted private keys to obtain the first aggregate value is as follows:

[0038] Among them, g is the generator of the cyclic group G, represents a random value chosen by the sender user for the receiver user, is the subkey of the sending user, is the public key of the recipient user, i is the current user, is the subkey of the current user, is the first aggregate value, The private key of the current user.

[0039] In some embodiments, the first aggregate value for each user in the second interaction Encrypt and send to the corresponding recipient user, numbered The user receives the The encrypted first aggregate value is in the form of , each user in the group will receive the encrypted first aggregate value of k-1 users, k is the number of users in the group, and the formula for the receiving user to aggregate all the received encrypted first aggregate values ​​to obtain the second aggregate value is as follows:

[0040] Among them, g is the generator of the cyclic group G, represents a random value chosen by the sender user for the receiver user, is the encrypted first aggregate value of the sending user, is the public key of the recipient user, i is the current user, is the minimum positive integer of the current user. is the second aggregate value.

[0041] In some specific embodiments, each user uses his own private key and the second aggregate value to perform a hash operation to obtain a group session key, which is expressed as follows:

[0042] in, is the group session key of user i, is the user subkey, SID is the session identifier, and H is the hash operation. The reason for performing the calculation to the k-2th power is so that the parameter calculations can cancel out.

[0043] Specifically, in the key negotiation method of this scheme through difference set expansion, each user only needs to transfer the key within the group, which greatly reduces the total amount of calculation required and effectively supports the rapid achievement of group key negotiation.

[0044] Embodiment 2 The present application also proposes a load-sharing group key negotiation method, including: Calculate the negotiation interaction model for each user in the blockchain using the same method as in the embodiment; Generate a public-private key pair for each user in the blockchain, and use each user as a sender user to perform the third interaction and the fourth interaction. In the third interaction, each sender user encrypts its own private key and sends it to the corresponding receiver user. The receiver user aggregates all the received encrypted private keys to obtain a third aggregate value, and adds a BLS signature to the third aggregate value to obtain a first signature value. In the fourth interaction, each sender user encrypts its own third aggregate value and sends it to the corresponding receiver user in conjunction with the first signature value. The receiver user aggregates all the received encrypted third aggregate values ​​to obtain a fourth encrypted aggregate value, and aggregates all the received first signature values ​​to obtain a second signature value. The interaction object in the negotiation interaction model corresponding to the sender user is the corresponding receiver user. Each user verifies the second signature value, and after passing the verification, uses its own private key and the fourth aggregate value to obtain the group session key through a hash operation.

[0045] Specifically, in the first embodiment, when the user is completely trusted and the transmitted message is authenticated, AKE security is achieved. To improve the security performance of the protocol, semi-trusted users are further considered, who may jointly modify the received subkeys, making the protocol vulnerable to key control attacks by internal attackers, so malicious attacks are avoided by adding BLS signatures.

[0046] Specifically, the specific method by which the receiving user aggregates all received encrypted private keys to obtain a third aggregate value and the method by which the receiving user aggregates all received encrypted third aggregate values ​​to obtain a fourth encrypted aggregate value are the same as those in Example 1 and are not described in detail here.

[0047] Specifically, a bilinear mapping is used and hash functions To perform BLS signature, it can resist malicious public key attacks.

[0048] Specifically, the signature calculation when attaching the BLS signature is:

[0049] Let the set T be , each receiving user passes To aggregate all received BLS signatures, where Indicates user The BLS signature of The initial value is .

[0050] Specifically, the formula for aggregating all received first signature values ​​to obtain the second signature value is as follows:

[0051] Specifically, the second signature value is verified by the following formula:

[0052] Specifically, the generation of the group session key and the same parameters in the above formula are the same as those in the first embodiment, and are not described in detail here.

[0053] Embodiment 3 This embodiment also provides an electronic device, referring to Figure 3, comprises a memory 404 and a processor 402, wherein the memory 404 stores a computer program, and the processor 402 is configured to run the computer program to execute the steps in any of the above method embodiments.

[0054] Specifically, the processor 402 may include a central processing unit (CPU), or an application specific integrated circuit (ASIC), or may be configured to implement one or more integrated circuits of the embodiments of the present application.

[0055] Among them, the memory 404 may include a large capacity memory 404 for data or instructions. For example, but not limitation, the memory 404 may include a hard disk drive (HDD), a floppy disk drive, a solid state drive (SSD), a flash memory, an optical disk, a magneto-optical disk, a tape, or a universal serial bus (USB) drive, or a combination of two or more of these. In appropriate cases, the memory 404 may include a removable or non-removable (or fixed) medium. In appropriate cases, the memory 404 may be inside or outside the data processing device. In a specific embodiment, the memory 404 is a non-volatile memory. In a specific embodiment, the memory 404 includes a read-only memory (ROM) and a random access memory (RAM). Where appropriate, the ROM may be a mask-programmed ROM, a programmable ROM (Programmable Read-Only Memory, PROM for short), an erasable PROM (Erasable Programmable Read-Only Memory, EPROM for short), an electrically erasable PROM (Electrically Erasable Programmable Read-Only Memory, EEPROM for short), an electrically alterable ROM (Electrically Alterable Read-Only Memory, EAROM for short) or a flash memory (FLASH) or a combination of two or more of these. In appropriate circumstances, the RAM may be a static random access memory (SRAM) or a dynamic random access memory (DRAM), wherein the DRAM may be a fast page mode dynamic random access memory 404 (FPMDRAM), an extended data output dynamic random access memory (EDODRAM), a synchronous dynamic random access memory (SDRAM), etc.

[0056] The memory 404 may be used to store or cache various data files required for processing and / or communication, as well as possible computer program instructions executed by the processor 402 .

[0057] The processor 402 reads and executes the computer program instructions stored in the memory 404 to implement any one of the difference set extended group key negotiation methods and the load balancing group key negotiation methods in the above embodiments.

[0058] Optionally, the electronic device may further include a transmission device 406 and an input / output device 408 , wherein the transmission device 406 is connected to the processor 402 , and the input / output device 408 is connected to the processor 402 .

[0059] The transmission device 406 can be used to receive or send data via a network. Specific examples of the above-mentioned network may include a wired or wireless network provided by a communication provider of the electronic device. In one example, the transmission device includes a network adapter (Network Interface Controller, referred to as NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 406 can be a radio frequency (Radio Frequency, referred to as RF) module, which is used to communicate with the Internet wirelessly.

[0060] The input / output device 408 is used to input or output information. In this embodiment, the input information may be a difference parameter, a public / private key pair of each user, etc., and the output information may be a group session key, etc.

[0061] Optionally, in this embodiment, the processor 402 may be configured to perform the following steps through a computer program: Generate a difference set, and calculate a negotiation interaction model for each user in the blockchain based on the difference set, wherein the negotiation interaction model defines the interaction objects of the user, and each user has the same number of interaction objects, and each user and all corresponding interaction objects in the negotiation interaction model are grouped as a group. In all groups, the number of times any two users appear together in different groups is a preset constant, wherein the interaction objects are other users in the blockchain; Generate a public-private key pair for each user in the blockchain, and use each user as a sender user to perform a first interaction and a second interaction. In the first interaction, each sender user encrypts its own private key and sends it to the corresponding receiver user, and the receiver user aggregates all the received encrypted private keys to obtain a first aggregate value; in the second interaction, each sender user encrypts its own first aggregate value and sends it to the corresponding receiver user, and the receiver user aggregates all the received encrypted first aggregate values ​​to obtain a second aggregate value, wherein the interaction object in the negotiation interaction model corresponding to the sender user is the corresponding receiver user; Each user uses his own private key and the second aggregate value to obtain the group session key through a hash operation.

[0062] It should be noted that the specific examples in this embodiment can refer to the examples described in the above embodiments and optional implementation modes, and this embodiment will not be described in detail here.

[0063] In general, various embodiments may be implemented in hardware or dedicated circuits, software, logic, or any combination thereof. Some aspects of the invention may be implemented in hardware, while other aspects may be implemented in firmware or software that may be executed by a controller, microprocessor, or other computing device, but the invention is not limited thereto. Although various aspects of the invention may be shown and described as block diagrams, flow charts, or using some other graphical representation, it should be understood that, as non-limiting examples, the boxes, devices, systems, techniques, or methods described herein may be implemented in hardware, software, firmware, dedicated circuits or logic, general-purpose hardware or controllers or other computing devices, or some combination thereof.

[0064] Embodiments of the present invention may be implemented by computer software that is executable by a data processor of a mobile device, such as in a processor entity, or by hardware, or by a combination of software and hardware. Computer software or programs (also referred to as program products) including software routines, applets and / or macros may be stored in any device-readable data storage medium, and they include program instructions for performing specific tasks. A computer program product may include one or more computer executable components configured to perform an embodiment when the program is run. One or more computer executable components may be at least one software code or a portion thereof. In addition, at this point, it should be noted that, for example, Figure 3 Any block of the logic flow in the program may represent program steps, or interconnected logic circuits, blocks and functions, or a combination of program steps and logic circuits, blocks and functions. The software may be stored on physical media such as memory chips or storage blocks implemented within a processor, magnetic media such as hard disks or floppy disks, and optical media such as, for example, DVDs and their data variants, CDs, etc. Physical media are non-transitory media.

[0065] Those skilled in the art should understand that the technical features of the above embodiments may be arbitrarily combined. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0066] The above embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the present application. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the attached claims.

Claims

1. A difference set extended group key negotiation method, characterized in that: The following steps are involved: Generate a difference set, and calculate a negotiation interaction model for each user in the blockchain based on the difference set, wherein the negotiation interaction model defines the interaction objects of the user, and each user has the same number of interaction objects, and each user and all corresponding interaction objects in the negotiation interaction model are grouped as a group. In all groups, the number of times any two users appear together in different groups is a preset constant, wherein the interaction objects are other users in the blockchain; Generate a public-private key pair for each user in the blockchain, and use each user as a sender user to perform the first interaction and the second interaction. In the first interaction, each sender user encrypts its own private key and sends it to the corresponding receiver user. The receiver user aggregates all the received encrypted private keys to obtain a first aggregate value. In the second interaction, each sending user encrypts its own first aggregate value and sends it to the corresponding receiving user, and the receiving user aggregates all the received encrypted first aggregate values ​​to obtain a second aggregate value, wherein the interaction object in the negotiation interaction model corresponding to the sending user is the corresponding receiving user; load-balanced group key negotiation method and high security; Each user uses his own private key and the second aggregate value to obtain the group session key through a hash operation.

2. A difference set extended group key negotiation method according to claim 1, characterized in that: In the step of "calculating a negotiation interaction model for each user in the blockchain based on a difference set", the difference set is normalized to obtain a normal difference set, and the normal difference set is cyclically bitwise modulo-added based on a preset extended parameter to obtain a group mapping table, and a negotiation interaction model is assigned to the users in the blockchain based on the group mapping table, wherein the extended parameter includes the number of users in the blockchain, the number of users in each group, and the number of times any two users appear together in different groups.

3. A difference set extended group key negotiation method according to claim 1, characterized in that: The first interaction and the second interaction are performed in a serial interaction manner, that is, an interaction order is assigned to each sending user. In the first interaction, each sending user encrypts its own private key according to the interaction order and sends it to the corresponding receiving user. In the second interaction, each sending user encrypts its own first aggregate value according to the interaction order and sends it to the corresponding receiving user.

4. A difference set extended group key negotiation method according to claim 1, characterized in that: The first interaction and the second interaction are performed in a parallel interaction manner, that is, in the first interaction, all sending users simultaneously encrypt their own private keys and send them to the corresponding receiving users, and in the second interaction, each sending user simultaneously encrypts its own first aggregate value and sends it to the corresponding receiving user.

5. A difference set extended group key negotiation method according to claim 1, characterized in that: The formula for the receiving user to aggregate all the received encrypted private keys to obtain the first aggregate value is as follows: ; Among them, g is the generator of the cyclic group G, represents a random value chosen by the sender user for the receiver user, is the subkey of the sending user, is the public key of the recipient user, i is the current user, is the subkey of the current user, is the first aggregate value, The private key of the current user.

6. A difference set extended group key negotiation method according to claim 1, characterized in that: The formula for the receiving user to aggregate all the received encrypted first aggregate values ​​to obtain the second aggregate value is as follows: ; Among them, g is the generator of the cyclic group G, represents a random value chosen by the sender user for the receiver user, is the encrypted first aggregate value of the sending user, is the public key of the recipient user, i is the current user, is the minimum positive integer of the current user. is the second aggregate value.

7. A difference set extended group key negotiation method according to claim 1, characterized in that: The formula for each user to obtain the group session key by hashing the private key and the second aggregate value is as follows: ; in, is the group session key of user i, SID is the session identifier, H is the hash operation, is the second aggregate value.

8. A load-balanced high-security group key negotiation method, characterized in that: include: Using the same method as in claim 1 to calculate a negotiation interaction model for each user in the blockchain; Generate a public-private key pair for each user in the blockchain, and use each user as a sender user to perform the third interaction and the fourth interaction. In the third interaction, each sender user encrypts its own private key and sends it to the corresponding receiver user. The receiver user aggregates all the received encrypted private keys to obtain a third aggregate value, and adds a BLS signature to the third aggregate value to obtain a first signature value. In the fourth interaction, each sender user encrypts its own third aggregate value and sends it to the corresponding receiver user in conjunction with the first signature value. The receiver user aggregates all the received encrypted third aggregate values ​​to obtain a fourth encrypted aggregate value, and aggregates all the received first signature values ​​to obtain a second signature value. The interaction object in the negotiation interaction model corresponding to the sender user is the corresponding receiver user. Each user verifies the second signature value, and after passing the verification, uses its own private key and the fourth aggregate value to obtain the group session key through a hash operation.

9. An electronic device comprising a memory and a processor, characterized in that: The memory stores a computer program, and the processor is configured to run the computer program to execute a difference set extended group key negotiation method according to any one of claims 1 to 7 or a load-balanced high-security group key negotiation method according to claim 8.

10. A readable storage medium, characterized in that: The readable storage medium stores a computer program, which includes a program code for controlling a process to execute a process, wherein the process includes a differential set extended group key negotiation method according to any one of claims 1 to 7 or a load-balanced high-security group key negotiation method according to claim 8.

Citation Information

Patent Citations

  • Data privacy fusion method and device

    CN113468601A

  • Hazardous waste block chain supervision system and method based on group key agreement

    CN114338016A

  • Method, system and equipment for implementing multicast service effective authentication and key distribution protocol

    CN114466318A

  • Method and device for producing encrypted data stream code

    CN1531244A